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Amendments to the Claims: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

Listing of Claims: 

Claim 1 (currently amended): A method of managing access by a client to user-specific 
information maintained in connection with a plurality of services offorod by a wob 
fiorvio e s provider and used by n usor of said plurality of c e rvic e s , the method comprising: 
maintaining a plurality of items of user-specific information in more than one of 
the a plurality of services offered bv a web-service s provider aq4 used bv a user of said 
plurality of services: 

obtaining a plurality of client access requests directed to accessing the plurality of 
items of user-specific information maintained in the more than one of the plurality of 
services, said plurality of access requests being translated from a task request that 
requires the client to access the plurality of items of user-specific information in order to 
complete the task request; 

invoking a consent management oyot e m determining if the client teeks has 
consent to access one of the plurality of items of user-specific information required by the 
client to complete the task request s ooid cons e nt management oyotom 

selectively obtaining consen t, from a party having autho rity to grant access to the 
client, for the client to access the one of the plurality of items of user-specific information 

tfre client lacks consent as a function of said determining for which tho client lacked 
consent to acc e s s; and 

filli ng the plurality of client access requests if the client has permi s sion consent to 
access each of the plurality of items of user-specific information in the more than one of 
the plurality of services. 

Claim 2 (original): The method of claim 1 further comprising: 

initiating the task request requiring the client to access the plurality of items of 
user-specific information in order to complete the task request; and 
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translating the task request into the plurality of client access requests to complete 
the task request. 

Claim 3 (currently amended): The method of claim 2 wherein selectively obtaining 
consent for the client to access the one of the plurality of items of user-specific 
information comprises: 

identifying the task request; 

placing the identified task request in a task queue; 

identifying [[a]] fee party with authority to grant consent to the client to access the 
one of the plurality of items of user-specific information for which the client lacked 

consent to access; and 

displaying a consent menu to the identified party with authority, said consent 
menu prompting the identified party to grant or deny consent for the client to access the 
one of the plurality of items of user-specific information for which the client lacked 
consent to access. 

Claim 4 (currently amended): The method of claim 3 wherein the identified party with 
authority to grant consent is the user of the plurality of services offered by the web- 
services provider and wherein displaying the consent menu to the identified party 
comprises displaying the consent menu to the user. 

Claim 5 (original): The method of claim 3 wherein the identified party with authority 
to grant consent is an owner of the one of the plurality of items of user-specific 
information for which the client lacked consent to access and wherein displaying the 
consent menu to the identified party comprises displaying the consent menu to the owner. 

Claim 6 (original): The method of claim 5 wherein the owner is the user of the 
plurality of services and wherein displaying the consent menu to the identified party 
comprises displaying the consent menu to the user. 
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Claim 7 (original): The method of claim 3 wherein the user of the plurality of services 
is a managed user and the identified party with authority to grant consent is a manager of 
the managed user and wherein displaying the consent menu to the identified party 
comprises displaying the consent menu to the manager of the managed user. 

Claim 8 (original): The method of claim 3 wherein displaying the consent menu to the 
identified party comprises: 

displaying an indication of the one of the plurality of items of user-specific 
information for which the client lacked consent to access; 

displaying an identity of the client; and 

displaying an intended use of the client of the one of the plurality of items of user- 
specific information for which the client lacked consent to access. 

Claim 9 (original): The method of claim 8 wherein displaying a consent menu to the 
identified party further comprises displaying a method of access requested by the client to 
complete the initiated task request. 

Claim 1 0 (original): The method of claim 8 wherein displaying a consent menu to the 
identified party further comprises displaying an indication of a status of each of the 
plurality of client access requests translated from the task request. 

Claim 1 1 (original): The method of claim 10 wherein displaying an indication of the 
status of each of the plurality of client access requests comprises displaying an indication 
of whether the client has consent from the identified party to access the plurality of items 
of user-specific information in the more than one of the plurality of services. 

Claim 12 (currently amended): The method of claim 3 wherein identifying the task 
request comprises: 

transmitting a took identifier to tho oonsont management oyat e m, said t aste 
identifier identifying the plurality of client access requests to complete the task request; 
and 
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identifying the one of the plurality of items of user-specific information for which 
the client lacked consent to access. 

Claim 1 3 (original): The method of claim 3 further comprising: 

providing a consent acceptance message being indicative of whether the identified 
party granted consent for the client to access the one of the plurality of items of user- 
specific information for which the client lacked consent; and 

updating an access control list associated with the one of the plurality of items of 
user-specific information for which the client lacked consent if the consent acceptance 
message indicates that the identified party granted consent, whereby upon updating said 
access control list, the client has consent to access the one of the plurality of items of 
user-specific infoimation. 

Claim 14 (original): The method of claim 13 further comprising removing the identified 
task from the task queue if the consent acceptance message indicates that the identified 
party granted consent. 

Claim 1 5 (original): The method of claim 1 3 further comprising transmitting a consent 
success message to the client, said consent success message being indicative of whether 
the identified party granted consent for the client to access the one of the plurality of 
items of user-specific information for which the client lacked consent 

Claim 16 (original): The method of claim 13 wherein updating the access control list 
further comprises setting a time limit in which the client has consent to access the one of 
the plurality of items of user-specific information. 

Claim 1 7 (original): The method of claim 3 wherein displaying the consent menu to the 
identified party further comprises displaying an invitation to allow the client enjoy a one- 
time only access to the one of the plurality of items of user-specific information for 
which the client lacked consent. 
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Claim 1 8 (original): The method of claim 3 wherein selectively obtaining consent for 
the client to access the one of the plurality of items of user-specific information further 
comprises sending an alert message to the party with authority to grant consent, said alert 
message alerting the party with authority to grant consent that the client seeks access to 
the one of the plurality of items of user-specific information for which the client lacked 
consent. 

Claim 19 (original): The method of claim 3 further comprising: 

providing a consent acceptance message being indicative of whether the identified 
party granted consent for the client to access the one of the plurality of items of user- 
specific information for which the client lacked consent; 

granting consent to allow the client to access the one of the plurality of items of 
user-specific information if the consent acceptance message indicates that the identified 
party granted consent. 

Claim 20 (original): One or more computer-readable media having computer-executable 
instructions for performing the method recited in claim 1. 

Claim 21 (currently amended): A task-based method of managing consent transactions in 
a network computing environment, said network computing environment including a 
web-services provider providing a first service and a second service, a user of the first 
service and the second service, and a client of the web-services provider, the method 
comprising: 

maintaining a first data store of user-specific information in connection with the 
first service; 

maintaining a second data store of user-specific information in connection with 
the second sendee; 

obtaining a first access request from the client and directed to the first service, 
said first access request indicating a first item of user-specific information maintained in 
the first data store to which the client seeks access in order to complete a task request; 
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obtaining a second access request from the client and directed to the second 
service, said second access request indicating a second item of user-specific information 
maintained in the second data store to which the client seeks access in order to complete 
the task request; 

determining if the client has consent to access the first item of user-specific 
information and the second item of user-specific information; 

invnkmg a onnsent manogomont system selectively obtaining consent if k4s 
dotormin e d that consent does not currently exist to allow the client to access the first item 
of user-specific information as a function of said determining, said consent manag e m ent 
nynt«m nftuHnntmg n eeaseftt ttinnngnmflnt trnnr.aotion oompriflinp wherein selectively 
obtaining consent includes : 

identifying a party with authority to grant consent to the client to access 

the first item of user-specific information; and 

displaying a consent menu to the identified party with authority, said 

consent menu prompting the identified party to grant or deny consent to the client 

to access the first item of user-specific information. 

Claim 22 (original): The method of claim 21 further comprising: 

initiating a task request from the user that requires the client to access the first 

item of user-specific information and the second item of user-specific information; and 
translating the task request into the first access request and the second access 

request. 

Claim 23 (currently amended): The method of claim 21 wherein invoicing th e consent 
management oyotom further oompris e s id e ntifying th e task roquoot and wherein 
eoadaetiag " ronftftnt mrmngBmont tranna etieft selectively obtaining consent further 
includes oompris e s : 

identifying the task request: 

retrieving a task manifest corresponding to the task request, said task manifest 
identifying the first and second items of user-specific information; and 

preparing an entry for display on the consent menu based on the task manifest. 



-7- 

PAGE 8/21 * RCVD AT 7/12«005 5:21:41 PM [Eastern Dayfight Time] 4 SVR:USPT0-EFXRF.1/2 a DN1S:8729306 * CS1D:3145881357 * DURATION (mn«s):07-02 



JUt-12-2005 TUE 04:26 PM SENNIGER POWERS LEAVITT 



FAX NO. 3145881357 



P. 09 



MS#300222.01 (MSFT 4969.1) 
PATENT 

Claim 24 (original): The method of claim 21 further comprising filling the second 
access request only if the client has consent to access both the first item of user-specific 
information and the second item of user-specific information. 

Claim 25 (original): One or more computer-readable media having computer- 
executable instructions for performing the method recited in claim 2 1 . 

Claim 26 (currently amended): A method of managing consent transactions in a network 
computing environment, said network computing environment including a web-services 
provider providing a plurality of services, a user of the plurality of services, said web- 
services provider maintaining user-specific information associated with the user in 
connection with the plurality of services, and a client of the web-services provider, said 
user initiating a task request with the client, said client directing a plurality of access 
requests to the plurality of services in order to complete the task request, the method 
comprising: 

selectively obtaining consent invoking a consent manag e m e nt proc e ss if the client 
lacks [[a]] consent required to complete one of the plurality of access requests, wherein 
said obtaining consent includes oonoont manag e m e nt proo e ss oomprioing : 

identifying a party with authority to grant consent to allow the client to 

complete the one of the plurality of access requests for which the client lacks 

consent; and 

initiating a consent request transaction with the identified party with 
authority to grant consent, said consent request transaction inviting the party with 
authority to grant consent to allow the client to complete the one of the plurality 
of access requests. 

Claim 27 (original): The method of claim 26 wherein initiating a consent request 
transaction further comprises displaying a consent menu to the identified party with 
authority to grant consent, said consent menu prompting the identified party to grant or 
deny consent for the client to complete the one of the plurality of access requests. 
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Claim 28 (original): The method of claim 27 wherein the identified party with authority 
to grant consent is the user of the plurality of services and wherein displaying the consent 
menu to said identified party comprises displaying the consent menu to the user. 

Claim 29 (original): The method of claim 27 wherein the identified party with authority 
to grant consent is an owner of the user-specific information associated with the user and 
wherein displaying the consent menu to said identified party comprises displaying the 
consent menu to the owner 

Claim 30 (original): The method of claim 27 wherein the user of the plurality of 
services is a managed user and the identified party with authority to grant consent is a 
manager of the managed user and wherein displaying the consent menu to said identified 
party comprises displaying the consent menu to the manager of the managed user 

Claim 3 1 (original): The method of claim 27 wherein prompting the identified party to 
grant or deny consent for the client to complete the one of the plurality of access requests 
comprises providing a one-time only consent option whereby when said identified party 
selects the one-time only consent option the client is allowed to complete the one of the 
plurality of access requests only for completing the task request. 

Claim 32 (original): The method of claim 26 wherein initiating the consent transaction 
with the party with authority to grant consent further comprises sending an alert message 
to said party with authority, said alert message alerting said party that the client is seeking 
access to the user-specific information. 

Claim 33 (original): One or more computer-readable media having computer- 
executable instructions for performing the method recited in claim 26. 

Claim 34 (original): A system for controlling access to user-specific information in a 
network computing environment, the system comprising: 
a web-services provider providing a service; 
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a user of the service, the web-services provider maintaining an item of user- 
specific information associated with the user in a data store associated with the service; 

a client of the web-services provider, said client operatively communicating with 
the user and seeking access to the item of user-specific information; 

an access control list associated with the item of user-specific information, said 
access control list indicating whether consent exists to allow the client to access the item 
of user-specific information; and 

a consent management system for controlling an update of the access control list, 
said consent management system initiating a consent transaction with a party having 
authority to grant consent to update the access control list when the access control list 
indicates that consent does not exist to allow the client to access the item of user-specific 
information* 

Claim 35 (original): The system of claim 34 wherein the consent management system 
comprises a consent user interface for displaying a consent menu to the party having 
authority to update the access control list, said consent menu prompting the identified 
party to grant or deny consent to allow the client to access the item of user-specific 
information, whereby if the identified party grants consent the consent management 
system operatively updates the access control list to indicate that the client has consent to 
access the item of user-specific information. 

Claim 36 (original): The system of claim 35 wherein the consent management system 
further comprises a consent server associated with the consent user interface for 
determining the party having authority to update the access control list and for 
operatively updating the access control list if the identified party grants consent to allow 
the client to access the item of user-specific information. 

Claim 37 (original): The system of claim 35 wherein the consent menu identifies a 
plurality of menu entries comprising: 
an identity of the client; 
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a method by which the client seeks to access the item of user-specific 
information; and 

a purpose for which the client seeks to access the item of user-specific 
information. 

Claim 38 (original): The system of claim 37 wherein the plurality of menu entries 
further comprises a value proposition associated with the purpose for which the client 
desires to access the first item of user-specific information. 

Claim 39 (original): A system for controlling access to user-specific information in a 
network computing environment, said system comprising: 
a user transmitting a task request; 

a web-services provider providing a first service and a second service, said web- 
services provider maintaining a first of item of user-specific information associated with 
the user in connection with the first service and a second item of user-specific 
information associated with the user in connection with the second service, said first and 
second services requiring consent before allowing access to the first and second items of 
user-specific information; 

a client in digital communication with the user and receiving the task request, said 
client translating the task request into a first access request and a second access request, 
said first access request being directed to the first service and seeking access to the first 
item of user-specific information and said second access request being directed to the 
second service and seeking access to the second item of user-specific information; and 

a consent management-system being selectively invoked by the client if the client 
lacks consent to access the first item of user-specific information, said consent 
management system identifying a party with authority to grant consent to the client to 
access the first item of user-specific information and initiating a consent request 
transaction with the party with authority to grant consent to the client to access the first 
item of user-specific information, said consent request transaction inviting the party with 
authority to grant consent to allow the client to access the first item of user-specific 
information. 



-11- 
PAGE 12/21 t RCVD AT 7/12/2005 5:21:41 PM [Eastern Daylight fine] * SVIfcUSPTO-EFXRF-1/2 1 DNIS:8729306 * CSB):3H5881357 1 DURATION (mm-ss):07-02 



JUL-12-2005 TUE 04:27 PM SENNIGER POWERS LEAVITT 



FAX NO. 3145881357 



P. 13 



MS#3O0222.01 (MSFT 4969.1) 
PATENT 

Claim 40 (original): The system of claim 39 wherein the consent management system 
further comprises a consent user interface for displaying a consent menu to the party with 
authority to grant consent to the client to access the first item of user-specific 
information. 

Claim 41 (original): The system of claim 40 wherein the consent menu identifies a 
plurality of menu entries comprising: 
an identity of the client; 

a method by which the client proposes to access the first item of user-specific 
information; and 

a purpose for which the client desires to access the first item of user-specific 
information. 

Claim 42 (original): The system of claim 41 wherein the plurality of menu entries 
further comprises a value proposition associated with the purpose for which the client 
desires to access the first item of user-specific information. 

Claim 43 (currently amended): A method of controlling access to user-specific 
information for use in connection with a network computing environment including a 
web-services provider, a user of a service provided by the web-services provider, and a 
client of the web-services provider, said web-services provider maintaining a data store 
of user-specific information associated with the user in connection with the service, and 
said client seeking access to an item of user-specific information in the data store and 
transmitting an access request message directed to the service and indicating the item of 
user-specific information in the data store to which the client seeks access, the method 
comprising: 

comparing the access request message to an access control list associated with the 
service, said access control list identifying whether the client has permission to access the 
item of user-specific information; 

placing the access request in a pending request queue; 



-12- 



PAGE 13/21 • RCVDAT 7/12/2D05 5:21:41 PM [Eastern Daylight Time] 1 SVfcUSPTO^FXM ' DMS:87293B6 • CSID:314S88135? t DURATION (mm-ss):0742 



M-12-2Q05 TUE 04:28 PM SENNIGER POWERS LEAVITT FAX NO. 3145881357 



P. 14 



MS#300222.01 (MSFT 4969.1) 
PATENT 

transmitting a service response message to the client, said service response 
message indicating a fault if the access control list identifies that the client does not have 
permission to access the item of user-specific information and said service response 
message indicating a success if the access control list identifies that the client has 
permission to access the item of user-specific information; 

selectively ob t*iTrin p cnnsenL from a party havi ng authority to grant consent tQ 
the client for the client to access the item of user - sp^ific information invoking a consent 
managomont system if the service response message received by the client indicates a 
fault; and 

filling the access request if the access control list authorizes the client to access 
the item of user-specific information in the data store and removing the access request 
from the pending request queue. 

Claim 44 (currently amended): The method of claim 43 wherein selectively obtaining 
consent further includes invoicing tho oono e nt manag e m e nt system further oompriooa : 

identifying a party with authority to grant permission to the client to access the 
item of user-specific information; and 

displaying a consent menu to the identified party with authority to grant 
permission, said consent menu prompting the identified party to grant or deny permission 
for the client to access the item of user-specific information. 

Claim 45 (original): The method of claim 44 wherein the identified party is the user of 
the service and wherein displaying a consent menu to the identified party comprises 
displaying the consent menu to the user. 

Claim 46 (original): The method of claim 44 wherein the identified party is an owner of 
the item of user-specific information and wherein displaying the consent menu to the 
identified party comprises displaying the consent menu to the owner. 

Claim 47 (original): The method of claim 44 wherein the user is a managed user and 
the identified party is a manager of the managed user and wherein displaying the consent 
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menu to the identified party comprises displaying the consent menu to the manager of the 
managed user. 

Claim 48 (original): One or more computer-readable media having computer- 
executable instructions for performing the method recited in claim 43. 
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